Guide

PIPEDA compliance checklist for small law firms

Legal I.T. services from DASTech ConsultingRelated serviceLegal I.T.See the service

PIPEDA, the Personal Information Protection and Electronic Documents Act, is Canada’s federal private-sector privacy law, and for a small law firm it comes down to a few plain-language duties: get meaningful consent before you collect or use a client’s personal information, protect that information with safeguards that match how sensitive it is, keep it only as long as you actually need it, be open about what you do with it, and be ready to act quickly if it is ever exposed. Client files hold some of the most sensitive personal data any business handles, so the safeguards expected of a firm sit at the higher end. Confirm with your own counsel whether PIPEDA or a substantially similar provincial privacy law governs your practice, and remember that whichever one applies, it runs alongside your Law Society obligations rather than replacing them.

Before you read on

This guide is general information about technology practice, not legal advice. It reflects what we see doing hands-on IT work with Canadian law firms, and it does not account for your firm’s particular circumstances. Confirm any specific obligation with your own counsel or with the Law Society directly before you act on it.

A quick note on scope: PIPEDA applies to organizations that collect, use, or disclose personal information in the course of commercial activity. How that plays out in a legal practice, and how it sits with solicitor-client privilege, is a question for your own counsel. What does not change is your professional duty of confidentiality. Rule 3.3-1 of the Law Society of Ontario’s Rules of Professional Conduct requires you to hold in strict confidence all information concerning the business and affairs of the client acquired in the course of the professional relationship, subject to four exceptions: where the client authorises disclosure, where disclosure is required by law or by a tribunal, where it is required by the Law Society, and where the rules otherwise permit it. Privacy law sits alongside that duty, not instead of it. When two rules overlap, treat the stricter one as the rule you follow.

Below is a numbered checklist of concrete controls. Work through it in order. None of it requires an enterprise budget, and most of it is configuration and habit rather than new software.

The PIPEDA checklist for a small firm

  1. Map what personal data you hold. You cannot protect what you have not counted. List every place client personal information lives: your practice management system, email, document storage, accounting software, paper files, and any personal devices. Note what is collected, why, and who can reach it. This inventory is the foundation for every control that follows.

  2. Handle consent properly. PIPEDA expects meaningful consent, which means the client should understand what you are collecting and why at the time you collect it. Your retainer and intake forms are the natural place to capture this. Collect only what the matter needs, and do not repurpose it for something unrelated without asking again.

  3. Lock down access with least privilege and MFA. Give each person access only to the files their role requires, and turn on multi-factor authentication (MFA) on email, your practice management system, and cloud storage. Access control is also part of how you meet the supervision rules in Chapter 6 of the Rules of Professional Conduct, which make you responsible for the work of non-licensee staff. MFA is the single highest-value control for a small firm because most breaches start with a stolen or guessed password. In our Heeney Lawyers cloud migration case study we reached 100% MFA coverage across the firm with zero downtime, which is a realistic target for a practice of any size.

  4. Encrypt data at rest and in transit. Data at rest means the files sitting on your laptops, servers, and backups. Data in transit means anything moving over the internet. Turn on full-disk encryption on every device (BitLocker on Windows, FileVault on Mac), insist on encrypted connections for email and client portals, and confirm your cloud providers encrypt stored data. Safeguards should be appropriate to the sensitivity of the information, and client information sits at the sensitive end of that scale.

  5. Set retention and secure disposal rules. Keep client personal information only as long as you have a legitimate need, then dispose of it securely. Professional obligations can set a floor that runs longer than the privacy answer: LSO By-Law 9 requires trust account records to be kept for ten years plus the current year, and a book of duplicate cash receipts for at least the six years preceding the most recent fiscal year end. Confirm the periods that apply to your other file types with the Law Society or your own counsel before you set a schedule. Emptying the recycle bin is not secure deletion. Use a proper secure-wipe tool for digital records and a cross-cut shredder for paper. Write your retention periods down so disposal becomes a routine, not a judgment call.

  6. Have a written breach response plan. Under PIPEDA you must report a breach of security safeguards to the Office of the Privacy Commissioner and notify affected individuals as soon as feasible after you determine that a breach has occurred, where that breach creates a real risk of significant harm. Significant harm covers bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record, and damage to or loss of property. The factors you weigh are the sensitivity of the information involved and the probability that it will be misused. Separately, you must keep a record of every breach, whether or not it meets that threshold, and retain those records for 24 months. Write down who to call, how you contain and assess an incident, and how you notify. A plan drafted calmly today beats decisions made in a panic later.

  7. Put privacy terms in every vendor agreement. Any provider that touches client data (cloud hosting, backup, IT support, e-discovery, even your email host) is handling information you remain accountable for. Handing data to a processor does not hand over the responsibility for it. Your agreements should state that the vendor protects the data to a comparable standard, uses it only for your purposes, and tells you promptly if they have a breach.

  8. Name someone accountable. PIPEDA expects a designated person responsible for privacy. In a small firm this is usually a partner. Their job is to own the policy, field client questions, and make sure the rest of this list actually happens.

  9. Publish a plain privacy policy. Be open about your practices. A short, readable privacy policy on your website and available to clients should explain what you collect, why, how you protect it, and how someone can see or correct their own information. PIPEDA expects both openness about your practices and a route for individuals to reach their own information, so keep the policy easy to find and easy to act on.

  10. Train the whole team. The best controls fail if someone clicks a phishing link or emails a file to the wrong recipient. A short annual session on phishing, safe file handling, and your breach plan keeps privacy a shared habit rather than one person’s problem. It also feeds a professional duty. Rule 3.1-1 defines a competent lawyer, and the commentary to the competence rule, Rule 3.1-2, says a lawyer should develop an understanding of, and ability to use, technology relevant to the nature and area of their practice, and should understand the benefits and risks of that technology given the duty to protect confidential information. The Law Society of Ontario adopted the Federation of Law Societies Model Code commentary on this point, amended in fall 2019.

The six core controls at a glance

Control area What to do What PIPEDA expects
Consent Collect only what the matter needs, explain why at intake Meaningful consent, given with an understanding of what you collect and why
Access and MFA Least-privilege access, MFA on every account Safeguards that match the sensitivity of the information
Encryption Full-disk encryption, encrypted email and portals Protection in storage and in transit, proportionate to sensitivity
Retention and disposal Written retention periods, secure deletion and shredding Keep personal information only as long as you have a legitimate need
Breach response Written plan, breach records, notify on real risk of significant harm Report and notify as soon as feasible on a real risk of significant harm, and keep a record of every breach for 24 months
Vendor agreements Comparable-protection and breach-notice clauses You stay accountable for information you hand to a provider to process

Get help working through the list

If you would rather have someone set these controls up for you, our legal IT services for law firms cover the whole list, and you can see what that looks like in practice in the Heeney Lawyers cloud migration case study. Not sure where your firm stands today? Reach us through our contact page and we will walk through it with you.

FAQ

Common questions.

Does PIPEDA apply to my small law firm?

PIPEDA applies to organizations that collect, use, or disclose personal information in the course of commercial activity. Whether that captures your firm, or whether a substantially similar provincial law governs you instead, is something to confirm with your own counsel or with the Law Society. Either way, the duty of confidentiality in Rule 3.3-1 still applies to you, and when the rules overlap you follow the stricter one.

Is MFA actually required by PIPEDA?

PIPEDA does not name specific technologies. It requires safeguards appropriate to the sensitivity of the data. For the highly sensitive information a law firm holds, MFA is a reasonable and expected baseline, which is why we treat it as non-negotiable for the firms we support.

When do I have to report a breach?

Report to the Privacy Commissioner and notify affected individuals as soon as feasible after you determine that a breach of security safeguards has occurred and that it creates a real risk of significant harm. The factors you weigh are the sensitivity of the information and the probability that it will be misused. You must also keep a record of every breach, whether or not it meets that threshold, and retain those records for 24 months. Build these notification steps into your plan now, before you need them.

How long can I keep client files?

Under PIPEDA, only as long as you have a legitimate need, then dispose of them securely. Professional rules can require longer. LSO By-Law 9 requires trust records to be kept for ten years plus the current year, and a book of duplicate cash receipts for at least the six years preceding the most recent fiscal year end. Confirm the periods for your other file types with the Law Society or your own counsel, then write your retention schedule down so it satisfies both PIPEDA and your professional obligations.